CIPA Fraud Detection Techniques & Reporting 3 — Questions and Answers
Question 1: Under the Fair Credit Reporting Act (FCRA), a consumer who discovers fraudulent accounts must notify which entity to place a fraud alert?
- All three major credit bureaus simultaneously
- Any one of the three major credit bureaus (Correct answer)
- The creditor who opened the fraudulent account
- The FTC directly
Correct answer: Any one of the three major credit bureaus
Under FCRA, notifying any one of the three major credit bureaus (Equifax, Experian, TransUnion) triggers them to notify the other two automatically.
Question 2: Geolocation mismatch fraud occurs when:
- A user's billing address does not match their shipping address
- A transaction's IP location conflicts with the cardholder's known location or billing address (Correct answer)
- A customer travels internationally and triggers a bank alert
- A device's GPS is disabled during a transaction
Correct answer: A transaction's IP location conflicts with the cardholder's known location or billing address
Geolocation mismatch flags occur when the IP address used for a transaction is in a different location than where the card was legitimately issued or used.
Question 3: Which type of fraud involves the unauthorized use of a person's existing account credentials to access and exploit their account?
- Account origination fraud
- Account takeover (ATO) fraud (Correct answer)
- Synthetic identity fraud
- First-party fraud
Correct answer: Account takeover (ATO) fraud
Account takeover fraud occurs when a fraudster obtains legitimate credentials (often via phishing or data breaches) and hijacks an existing account.
Question 4: A CIPA advisor recommending a 'freeze' versus a 'fraud alert' should know that a security freeze:
- Lasts 90 days and is placed by the creditor
- Requires a police report to activate
- Blocks new credit from being opened without the consumer lifting the freeze (Correct answer)
- Alerts lenders to verify identity but does not block new credit
Correct answer: Blocks new credit from being opened without the consumer lifting the freeze
A security freeze (credit freeze) restricts access to the credit report entirely, preventing new accounts from being opened, whereas a fraud alert only asks creditors to verify identity.
Question 5: Which machine learning approach is commonly used in fraud detection to handle highly imbalanced datasets where fraud cases are rare?
- Linear regression
- Oversampling techniques such as SMOTE (Correct answer)
- Principal component analysis (PCA)
- K-means clustering
Correct answer: Oversampling techniques such as SMOTE
SMOTE (Synthetic Minority Oversampling Technique) creates synthetic fraud examples to balance the dataset, improving model sensitivity to rare fraud events.
Question 6: The primary purpose of a Currency Transaction Report (CTR) is to report:
- Any transaction involving international wire transfers
- All cash transactions exceeding $10,000 in a single business day (Correct answer)
- Suspicious activity regardless of dollar amount
- Credit card purchases over $10,000
Correct answer: All cash transactions exceeding $10,000 in a single business day
CTRs are required by the Bank Secrecy Act for cash transactions exceeding $10,000, helping detect money laundering and structuring attempts.
Question 7: Social engineering detection in fraud prevention focuses on identifying attempts to:
- Exploit software vulnerabilities in banking systems
- Manipulate individuals into divulging sensitive information or performing actions (Correct answer)
- Install malware on corporate networks
- Intercept encrypted communications between parties
Correct answer: Manipulate individuals into divulging sensitive information or performing actions
Social engineering exploits human psychology rather than technical vulnerabilities, making detection dependent on recognizing manipulative communication patterns.
Under the Fair Credit Reporting Act (FCRA), a consumer who discovers fraudulent accounts must notify which entity to place a fraud alert?